CVE-2026-21727

low Grafana
CVSS v3 Base Score
3.3
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.2%
Exploitation probability in 30 days
Top 89% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Confidentiality
Low
Integrity
Low
Availability
None
Published: April 15, 2026 (144 days ago)
Last Modified: August 19, 2026
Vendor: Grafana
Source: NVD

Description

A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization. This issue affects correlations created prior to Grafana 10.2 and is fixed in >=11.6.11, >=12.0.9, >=12.1.6, and >=12.2.4. Thanks to Gyu-hyeok Lee (g2h) for reporting this vulnerability.

CWE

CWE-732

Affected Products

grafana grafana

References